2023 Threat Landscape
CF: What do you think will be most challenging and worrisome about the threat landscape the rest of 2023?
CB: The key word there is 2023. The threat landscape is always changing. When you know you have one area of the threat landscape figured out, guess what, the adversary will figure out another path. And that’s the fascinating thing about the threat landscape.
But let me touch on business email compromise (BEC). We’ve seen in the past year from our incident response engagements that the amount of engagements from BEC has doubled. So what keeps me up at night is whenever you see one vector of the threat landscape double in a year, you know that’s concerning. If you look a year ago, it was more ransomware. Now we’re seeing definitely the growth coming from BEC. And BECs are really a path that a human has to make the right decision on whether or not to open an email, for example. And whenever there’s a human, there’s a vector that the human has to make the right path, so that’s why training is important — training your staff to make sure they understand not to open what could potentially be malicious.